Local guardrail proxy that blocks destructive MCP tool calls, rug pulls, and tool poisoning
is a tiny, local MCP guardrail that sits between your AI coding agent (Cursor, Claude Code, …) and the real MCP servers your agent talks to (postgres, github, shell, filesystem, …) — local stdio servers and, since v0.9, remote Streamable HTTP ones. On every it evaluates 50+ adaptive safety rules (plus an optional 40-rule community pack) across eight destructive surfaces — SQL, git, filesystem,…
La verifica conferma l’identità del publisher (la proprietà del repo), non la sicurezza del codice. L’analisi di sicurezza copre i CVE noti e gli script di installazione sospetti.
Forge ha letto 0 file sorgente da l’archivio del repository e non ha trovato alcuna registrazione di strumenti MCP. L’estrazione si basa su schemi applicati al codice distribuito: un server che costruisce l’elenco degli strumenti a runtime, o che distribuisce solo codice impacchettato o minificato, non registra nulla di visibile qui. Va letto come «non rilevato», non come «non ne espone nessuno».
is a tiny, local MCP guardrail that sits between your AI coding agent (Cursor, Claude Code, …) and the real MCP servers your agent talks to (postgres, github, shell, filesystem, …) — local stdio servers and, since v0.9, remote Streamable HTTP ones. On every it evaluates 50+ adaptive safety rules (plus an optional 40-rule community pack) across eight destructive surfaces — SQL, git, filesystem, secrets exfiltration, supply-chain RCE, reverse shells, sudo / privilege escalation, cloud…
Questa voce non pubblica alcun pacchetto npm, quindi Forge non ha un albero delle dipendenze per essa. È una lacuna di copertura, non l'affermazione che non abbia dipendenze.